Security Hotspot issues are meant to help developers during their code review. They point to locations in the code where vulnerabilities often hide. They do not impact the quality gate. During the review the developer can change issue the status to:

“detect” which will change the issue type to “Vulnerability”.

“Dismiss” which will mark the issue as “Won’t fix”.

The description of each rule explains the kind of vulnerabilities that can be expected and what are the best practices.